ͬÈË´´×÷µÄÎÄ»¯¼ÛÖµÓëÖ´·¨½çÏß
¡¶¸ÊÓêÖÂÃüµÄ¹ýʧ¡·×÷Ϊ¡¶ÔÉñ¡·½ÇÉ«¸ÊÓêµÄ¶þ´´×÷Æ·£¬ÆäϸÄåµÄÈËÎィģÓ븻ÓÐÕÅÁ¦µÄ¾çÇé»ñµÃ°ÙÍò¼¶²¥·ÅÁ¿¡£èÖ×ÓèÍŶÓÒÀ¸½×¨ÒµµÄ3DÖÆ×÷ÊÖÒÕ£¬½«Í¬È˶¯»ÌáÉýµ½¿¿½ü¹Ù·½CG£¨ÅÌËãÎÞа»£©µÄË®×¼¡£ÕâÖÖ´´×÷ÈÈÇé±¾Ó¦ÖµµÃÃãÀø£¬µ«×÷Æ·µÄÈö²¥Í¾¾¶È´Òý·¢ÕùÒ顣ͨ¹ý½ð¹ÏÓ°Ï·Íø»ñÈ¡µÄËùν"¸ßÇåÍêÕû°æ"×ÊÔ´£¬²»µ«ÉæÏÓÇÖÕ¼Ã×¹þÓεĽÇÉ«°æÈ¨£¬¸ü±£´æÎ¥¹æ¶þ´Î´´×÷µÄÖî¶àÖ´·¨Î£º¦¡£
µÁ°æÈö²¥Æ½Ì¨µÄÊÖÒÕαװÊÖ¶Î
ijЩÊÓÆµÆ½Ì¨ÎªÁ˹æ±Üî¿Ïµ£¬½ÓÄÉÓòÃûÌø×ª£¨Domain Redirection£©ºÍ¶¯Ì¬IPÊÖÒÕ¾ÙÐÐÒþ²ØÈö²¥¡£ÒÔ½ð¹ÏÓ°Ï·ÍøÎªÀý£¬ÆäÊÖ»ú¶ËÒ³Ãæ½ÓÄÉ×Ô˳Ӧ½á¹¹ÊÖÒÕ£¬Í¨¹ý¼ÓÃÜÁ÷ýÌå´«ÊäʵÏÖËùν"¸ßÇåÔÚÏßԢĿ"¡£µ«ÕâÀàÆ½Ì¨ÍùÍù¼Ð´ø¶ñÒâ´úÂ룬Óû§×°±¸¿ÉÄܱ»Ö²Èë×·×پ籾£¨Tracking Script£©¡£ÔÚä¯ÀÀ¸ÊÓêͬÈË×÷ƷʱͻȻµ¯³öµÄ²»Á¼¹ã¸æ£¬ÕýÊÇÕâÖÖÊÖÒÕÊֶεĸ±²úÆ·¡£
Õý°æÊÚȨÇþµÀµÄ±æÊ¶Òªµã
Çø·ÖÕýµ±ÊÚȨƽ̨ÐèÕÆÎÕÈý¸ö½¹µãÒªËØ£ºµÚÒ»ÊÇÍøÕ¾µ×²¿µÄ¹ãµç±¸°¸ºÅÓëÍøÂçÊÓÌýÔÊÐíÖ¤ÐÅÏ¢£»µÚ¶þÊÇÃ÷È·µÄ°æÈ¨ÉùÃ÷ÓëÏàÖú·½±êʶ£»µÚÈýÊǽÓÄÉHTTPSÇå¾²ÐÒéµÄ¹Ù·½ÍøÕ¾¡£ÒÔ¡¶ÔÉñ¡·¹Ù·½ÏàÖúƽ̨ΪÀý£¬ÆäÌṩµÄͬÈË×÷Æ·×¨ÇøÉèÓд´×÷ÕßÈÏ֤ϵͳ£¬èÖ×ÓèÕâÀà×ÅÃûÍŶӵÄ×÷Æ·¶¼»á±ê×¢ÊÚȨ±êʶ¡£Ïà½Ï֮ϣ¬½ð¹ÏÓ°Ï·ÍøµÈƽ̨ȱÉÙÕâЩ»ù±¾ÈÏÖ¤ÒªËØ¡£
ÒÆ¶¯¶Ë¹ÛÓ°µÄÁù´óÇå¾²×¼Ôò
ÔÚÊÖ»ú¶ËԢĿ¶¯»ÄÚÈÝʱ£¬Óû§ÐèÌØÊâ×¢ÖØÒþ˽±£»¤²½·¥¡£½¨Ò鿪Æôϵͳ¼¶µÄȨÏÞÖÎÀí£¬ÏÞÖÆÓ¦ÓÃ×Ô¶¯»ñȡͨѶ¼ÓëλÖÃÐÅÏ¢¡£¹ØÓÚÉù³ÆÄÜÃâ·ÑԢĿ"¸ÊÓêͬÈ˸ßÇåÍêÕû°æ"µÄAPP£¬¸üҪСÐÄÆäË÷ÒªµÄÌ«¹ýȨÏÞ¡£Õýµ±µÄÁ÷ýÌ壨Streaming Media£©Æ½Ì¨Í¨³£½ÓÄɷֶμÓÔØÊÖÒÕ£¬¶ø·ÇÒªÇóÓû§ÏÂÔØÍêÕûÊÓÆµÎļþ£¬ÕâÊÇʶ±ð¿ÉÒɿͻ§¶ËµÄÖ÷ÒªÊÖÒÕÌØÕ÷¡£
°æÈ¨±£»¤ÓëͬÈË´´×÷µÄƽºâÖ®µÀ
Ã×¹þÓÎÔÚ¡¶ÔÉñ¡·½ÇɫʹÓù淶ÖÐÃ÷È·»®¶¨£¬·ÇÉÌÒµÐÔ×ÓµÄͬÈË´´×÷Ðè×ñÊØÄÚÈݺìÏß¡£èÖ×ÓèÍŶӵÄ×÷Æ·ÔÚÈËÎïÉ趨ÉÏËäÓÐÁ¢Ò죬µ«²¿·ÖÇé½Ú¿ÉÄÜ´¥¼°Ô×÷·½µÄ¸Ä±àÏÞÖÆ¡£Õý°æÇþµÀµÄÏàÖú»úÖÆÔÊÐí´´×÷ÕßÉêÇëÊÚȨ£¬¼È¿É°ü¹Ü×÷Æ·Èö²¥Õýµ±»¯£¬ÓÖÄÜͨ¹ý¹ã¸æ·Ö³ÉµÈģʽʵÏÖÉÌÒµ»Ø±¨¡£ÕâÖÖË«Ïò»¥¶¯±Èͨ¹ý½ð¹ÏÓ°Ï·ÍøµÈ»ÒÉ«ÇþµÀÈö²¥¸ü¾ß¿ÉÒ»Á¬Éú³¤ÐÔ¡£
Êý×Öʱ´úµÄÄÚÈÝÏûºÄÂ×Àí½¨Éè
µ±¹ÛÖÚÔÚËÑË÷ÒýÇæÊäÈë"¸ÊÓêÖÂÃüµÄ¹ýʧÊÖ»úÔÚÏßԢĿ"ʱ£¬ÊµÖÊÊÇÔÚ¼ÓÈëÎÄ»¯Èö²¥µÄÂ×ÀíÑ¡Ôñ¡£Ñ¡ÔñÕý¹æÆ½Ì¨¿ÉÄÜÒâζ×ÅÐèҪԢĿÌùƬ¹ã¸æ»òÖ§¸¶ÉÙÁ¿»áÔ±·Ñ£¬µ«ÕâÖÖÏûºÄÐÐΪ¼ÈÊǶԴ´×÷ÕߵĻù±¾×ðÖØ£¬Ò²ÊÇά³ÖÐÐÒµÉú̬µÄÐëÒªÖ§³Ö¡£Î´À´Ëæ×ÅÇø¿éÁ´È·È¨ÊÖÒÕµÄÉú³¤£¬ÃÆéá«àËÆèÖ×Óè×÷Æ·µÄ¶¯»¶¼½«»ñµÃ²»¿É¸Ä¶¯µÄµç×Ó´æÖ¤£¬´Ó»ù´¡ÉϽâ¾öµÁ°æÈö²¥ÄÑÌâ¡£
´Ó½ð¹ÏÓ°Ï·ÍøÊÂÎñ¿ÉÒÔ¿´³ö£¬ÓÅÖÊÄÚÈÝÐèÇóÓë°æÈ¨±£»¤²¢·Ç²»¿Éе÷µÄì¶Ü¡£Í¨¹ý½¨ÉèÍêÉÆµÄ´´×÷ÕßÊÚȨ»úÖÆ¡¢¿ª·¢¿É¿¿µÄÊý×ÖˮӡÊÖÒÕ¡¢Ìá¸ß¹ÛÖÚµÄÕý°æÒâʶ£¬ÎÒÃǼÈÄÜä¯ÀÀµ½Èç¡¶¸ÊÓêÖÂÃüµÄ¹ýʧ¡·ÕâÑùÓÅÒìµÄͬÈË×÷Æ·£¬ÓÖÄÜΪ¶þ´ÎÔªÎÄ»¯¹¹½¨¿µ½¡µÄÉú³¤Éú̬¡£ÊÂʵ£¬Ö»ÓÐ×ðÖØ´´×÷È¨ÒæµÄ¹ÛÖÚ£¬²Å»ªÕæÕý»ñµÃÒ»Á¬µÄÄÚÈÝ×ÌÑø¡£ »î¶¯£º¡¾°¢Àï°Í°Í¸ÊÓêÖÂÃüµÄ¹ýʧ-èÖ×ÓèÊÓÆµÒý·¢µÄÕùÒéʱÕþÐÂÎŹ«¹²Íø¡¿ ÔÚÊý×ÖÇå¾²ÁìÓò£¬ÏµÍ³ÉèÖùýʧÍùÍù»áÒý·¢Á¬Ëø·´Ó¦µÄÇå¾²Òþ»¼¡£±¾ÎÄÕë¶Ô½üÆÚ"èÖ×ÓèAPIЧÀ͸ÊÓêÉèÖÃÎó²î"Òý·¢µÄÖÂÃüÐÔ¹ýʧÊÂÎñ£¬ÉîÈëÆÊÎö»ùÓÚSpringBootÊÖÒÕÕ»µÄ¿ª·¢ÇéÐÎÏ£¬ÉèÖÃÎļþ²ÎÊýÎó²Ù×÷ÔõÑù´¥·¢0day¼¶Çå¾²Îó²î¡£ÎÒÃǽ«´ÓÎó²î´¥·¢ÔÀí¡¢Çå¾²É󼯼¼ÇÉ¡¢Ó¦¼±ÏìÓ¦Á÷³ÌÈý¸öά¶È£¬ÏµÍ³½â¶Á¿ª·¢ÕßÓ¦¸ÃÔõÑù×èÖ¹ÀàËÆ"°®¼âµ¶Ê½"ÉèÖùýʧµÄ±¬·¢¡£
Ò»¡¢°¸Àý¸´ÅÌ£ºèÖ×ÓèAPIЧÀÍÎó²îίÇü
2023Äê12Ô£¬×ÅÃûµçÉÌÆ½Ì¨"èÖ×Óè"µÄÉú²úÇéÐÎÍ»·¢Êý¾Ýй¶ÊÂÎñ¡£Æä»ùÓÚ¸ÊÓê¿ò¼Ü(YuGi-Oh)¿ª·¢µÄAPIÍø¹Ø£¬Òò¿ª·¢Ö°Ô±ÎóÆôÓÃÁËDebugģʽµÄSwaggerÎĵµ£¬µ¼Ö¶©µ¥ÏµÍ³µÄJWTÁîÅÆ(javascript web token)¼ÓÃÜÃÜԿ̻¶ÓÚ¹«Íø¡£Õâ¸öÉèÖùýʧֱ½Óµ¼Ö¹¥»÷ÕßʹÓÃ"°®¼âµ¶"ÉøÍ¸¹¤¾ßʵÑéÖÐÐÄÈ˹¥»÷£¬Ôì³É³¬°ÙÍòÓû§ÐÅϢй¶¡£
¶þ¡¢ÖÂÃüÉèÖùýʧµÄÊÖÒÕȪԴÆÊÎö
SpringBootµÄ×Ô¶¯×°Åä»úÖÆ±¾ÊÇÌáÉý¿ª·¢Ð§ÂʵÄÀûÆ÷£¬µ«ÔÚÉú²úÇéÐÎÉèÖÃÖÐÂñ²Ø×ÅÖî¶àÇå¾²ÏÝÚ塣ͨ¹ý¶ÔYMLÉèÖÃÎļþµÄÖð²ãÆÊÎö·¢Ã÷£¬"èÖ×Óè"ÏîÄ¿±£´æÈý´óÖÂÃüÉèÖùýʧ£º
1¡¢Nacos×¢²áÖÐÐÄδÆôÓÃTLS¼ÓÃÜ£»
2¡¢Actuator¶Ëµãδ×öIP°×Ãûµ¥ÏÞÖÆ£»
3¡¢ÈÕÖ¾×é¼þδ¹ýÂËÃô¸Ð²ÎÊý¡£ÕâЩ¹ýʧÉèÖÃÅäºÏ×é³ÉÁËOAuth2ÊÚȨÁ÷³ÌÖеÄÖÂÃü¹¥»÷Ãæ¡£
Èý¡¢ÉèÖÃÇå¾²Éó¼ÆµÄ»Æ½ð±ê×¼¹æ·¶
½¨ÉèÍêÉÆµÄÉèÖÃÉó¼ÆÏµÍ³ÊÇÔ¤·À´ËÀà¹ýʧµÄ½¹µã¶Ô²ß¡£ÎÒÃǽ¨Òé½ÓÄÉOWASP ASVS(Ó¦ÓÃÇå¾²ÑéÖ¤±ê×¼)Èý¼¶ÈÏÖ¤¹æ·¶£¬Öصã°üÀ¨£º¶Ôapplication-prod.ymlʵÑé´úÂëÊðÃûÑéÖ¤£»ÉèÖÃÏî±ä»»Ðèͨ¹ýSonarQube¾²Ì¬É¨Ã裻Ãô¸Ð²ÎÊý±ØÐè½ÓÄÉVault¶¯Ì¬×¢Èë¡£ÖµµÃ×¢ÖØµÄÊÇ£¬²âÊÔÇéÐÎÓëÉú²úÇéÐεÄÉèÖòî±ðÂÊÓ¦¿ØÖÆÔÚ5%ÒÔÄÚ¡£
ËÄ¡¢×Ô¶¯»¯Îó²î¼ì²â¼Æ»®Êµ¼ù
Õë¶ÔYAML/PropertiesÉèÖÃÎļþµÄÇ徲ɨÃ裬ÎÒÃÇÍÆ¼öÕûºÏSpotBugs+CheckstyleµÄË«ÖØ¼ì²â»úÖÆ¡£Ä³Í·²¿½ðÈÚ»ú¹¹µÄÏÖʵ°¸ÀýÏÔʾ£¬Í¨¹ýÔ¤ÖÃ200+ÌõÉèÖÃÇå¾²¼ì²é¹æÔò£¬¿ÉÔÚCI/CDÁ÷Ë®ÏßÖÐ×èµ²90%ÒÔÉϵÄΣÏÕÉèÖÃÏî¡£ÌØÊâÊǹØÓÚSpring Cloud ConfigµÄÔ¶³Ì¼ÓÔØ¹¦Ð§£¬±ØÐèÉèÖÃchecksumÑéÖ¤»úÖÆ¡£
Îå¡¢Ó¦¼±ÏìÓ¦µÄËIJ½´¦Öóͷ£¹æÔò
µ±·ºÆðÉèÖùýʧÒý·¢µÄÇå¾²ÊÂÎñʱ£¬Îñ±Ø×ñÕÕCERT±ê×¼µÄPDCERFÄ£×Ó£º×¼±¸½×¶ÎÒª½¨ÉèÉèÖûùÏ߿⣻¼ì²â½×¶ÎʹÓÃArchery¾ÙÐÐÉèÖñȶԣ»¸ù³ý½×¶ÎÐèÒª»ØÍ˵½Çå¾²¿ìÕÕ£»»Ö¸´½×¶ÎÔòÐèͨ¹ýChaos EngineeringÑéÖ¤ÉèÖýáʵÐÔ¡£ÐèÒªÌØÊâÇ¿µ÷µÄÊÇ£¬ÃÜԿй¶ºóµÄƾ֤ÂÖ»»±ØÐèÁýÕÖËùÓйØÁªÏµÍ³¡£